Know your enemy "better"

After analysing attack against an ISP with another VX brother via Honeypot (www.honeynet.org), there is a different interpretation to me (15-day deployment since 22 Feb):

Top 10 Attackers31111|86.63.108.22610337|189.83.55.7110278|95.162.64.2529235|189.83.120.256643|176.62.121.2475122|189.83.29.133712|186.50.142.73638|124.247.203.1143233|186.237.36.1042769|128.71.208.199

For the binaries and malware downloaded from attackers' hosts:347d214c8224fc47552addaf91609157|86.63.108.226|15437c3852074ee50da92c2857d24471747d9|189.83.55.71|50977942a56800f2d4e16f95169793c66851|95.162.64.252|5052c3852074ee50da92c2857d24471747d9|189.83.120.25|45249f163e7ea43ec22df3e74fb45e7dffb7|176.62.121.247|3255c3852074ee50da92c2857d24471747d9|189.83.29.13|258987136c488903474630369e232704fa4d|186.50.142.7|185487136c488903474630369e232704fa4d|124.247.203.114|18176b54e187a3a6971ffe03e9aea5afcacc|186.237.36.104|160587136c488903474630369e232704fa4d|186.55.6.68|118987136c488903474630369e232704fa4d|186.55.58.40|11669f163e7ea43ec22df3e74fb45e7dffb7|94.137.25.4|100787136c488903474630369e232704fa4d|186.50.134.101|86887136c488903474630369e232704fa4d|81.181.40.16|837c3852074ee50da92c2857d24471747d9|190.38.89.60|62887136c488903474630369e232704fa4d|186.55.63.9|54187136c488903474630369e232704fa4d|186.53.104.240|529c3852074ee50da92c2857d24471747d9|186.95.68.103|46087136c488903474630369e232704fa4d|186.55.0.148|4349f163e7ea43ec22df3e74fb45e7dffb7|178.74.117.104|3819f163e7ea43ec22df3e74fb45e7dffb7|46.233.199.247|375c3852074ee50da92c2857d24471747d9|190.72.22.126|3696b54e187a3a6971ffe03e9aea5afcacc|186.237.39.219|3639f163e7ea43ec22df3e74fb45e7dffb7|176.62.99.151|356b081022fc581decf4c8640dbc74a9198|186.51.223.218|3479f163e7ea43ec22df3e74fb45e7dffb7|178.74.91.140|310c3852074ee50da92c2857d24471747d9|186.95.67.198|26887136c488903474630369e232704fa4d|186.53.99.170|231393e2e61ff08a8f7439e3d2cfcb8056f|117.222.195.168|2046b54e187a3a6971ffe03e9aea5afcacc|186.237.40.123|1819f163e7ea43ec22df3e74fb45e7dffb7|46.233.240.154|159b0ace06ed2168781136f13fac6bb1037|37.204.119.122|15687136c488903474630369e232704fa4d|186.55.8.217|1406b54e187a3a6971ffe03e9aea5afcacc|186.237.36.32|139393e2e61ff08a8f7439e3d2cfcb8056f|95.30.95.61|1366b54e187a3a6971ffe03e9aea5afcacc|186.237.40.90|115393e2e61ff08a8f7439e3d2cfcb8056f|128.71.48.99|8587136c488903474630369e232704fa4d|186.55.33.220|8487136c488903474630369e232704fa4d|186.55.4.119|8494e689d7d6bc7c769d09a59066727497|176.237.252.212|770c1fa21d2ae6374e1e2f754504d7c084|95.46.91.179|73393e2e61ff08a8f7439e3d2cfcb8056f|2.95.63.148|680c1fa21d2ae6374e1e2f754504d7c084|95.46.86.52|64ac851fdca8a7f4b5a185c9686165586f|190.68.43.12|626b54e187a3a6971ffe03e9aea5afcacc|186.237.38.221|609c09418c738e265a27e6c599f43d86ab|93.81.212.191|509f163e7ea43ec22df3e74fb45e7dffb7|94.137.36.57|4287136c488903474630369e232704fa4d|186.53.96.33|419f163e7ea43ec22df3e74fb45e7dffb7|109.120.44.63|409f163e7ea43ec22df3e74fb45e7dffb7|94.137.40.62|400c1fa21d2ae6374e1e2f754504d7c084|95.46.92.243|376b54e187a3a6971ffe03e9aea5afcacc|186.237.37.157|36393e2e61ff08a8f7439e3d2cfcb8056f|117.222.196.3|349f163e7ea43ec22df3e74fb45e7dffb7|178.74.65.56|32c3852074ee50da92c2857d24471747d9|189.83.63.113|3287136c488903474630369e232704fa4d|186.50.137.177|299f163e7ea43ec22df3e74fb45e7dffb7|176.62.102.75|28393e2e61ff08a8f7439e3d2cfcb8056f|128.71.48.119|17c3852074ee50da92c2857d24471747d9|124.107.74.198|16393e2e61ff08a8f7439e3d2cfcb8056f|117.203.204.43|138c9367b7dc43dadaa3ec9da767c586cf|175.182.21.32|139c09418c738e265a27e6c599f43d86ab|93.81.222.198|13

Attack comes from various countries from Brazil, Poland, Russia, Romania, India but "China". A honeypot is set up in a private company for 2 months, the top 10 attackers from servers in China. The active one is from AS9800 . I would say, this is the difference between general and target attack. I have notified the affected company and hopefully he could be alerted and make corresponding action on it.